mirror of
https://github.com/fscotto/infra.git
synced 2026-10-03 13:29:58 +00:00
Prepare isolated rootless Gitea Quadlet on Atlas
This commit is contained in:
12
AGENTS.md
12
AGENTS.md
@@ -57,6 +57,8 @@ Ansible-driven personal infrastructure repo for Fedora and Void desktops, Fedora
|
||||
- Server compose render: `podman-compose -f /opt/docker/server/docker-compose.yml config` and `systemctl status podman-compose-server`
|
||||
- Atlas media stack:
|
||||
`ansible-playbook ansible/site.yml --limit atlas --tags storage,sharing,containers --check --diff`
|
||||
- Atlas rootless Gitea staging (does not start Gitea):
|
||||
`ansible-playbook ansible/site.yml --limit atlas --tags gitea --check --diff`
|
||||
- Atlas network/share hardening:
|
||||
`ansible-playbook ansible/site.yml --limit atlas --tags hardening,sharing --check --diff`
|
||||
- Atlas ZFS snapshot retention and scrub timers:
|
||||
@@ -263,9 +265,13 @@ successfully. The first monthly scrub remains a runtime check.
|
||||
- [x] Design the staged Prometheus-to-Atlas Gitea migration in `docs/atlas-gitea-migration.md`.
|
||||
The approved topology keeps NPM on Prometheus and moves HTTPS and public SSH (TCP/2222) together;
|
||||
Gitea must run as a dedicated rootless user Quadlet on Atlas. The rootful-to-rootless data-layout
|
||||
conversion requires an isolated restore test. No data has been moved or traffic changed.
|
||||
- [ ] Prepare a separate Atlas Gitea dataset, disabled rootless user Quadlet, and isolated restore test from the
|
||||
verified Prometheus backup; validate SQLite, repositories, SSH host keys, and target backups.
|
||||
conversion requires an isolated restore test. No Gitea data has been moved or traffic changed.
|
||||
- [x] Prepare the dedicated Atlas Gitea dataset, non-login UID/GID 1101 with a separate rootless Podman
|
||||
sub-ID range, and disabled user Quadlet. On 2026-10-01 the targeted Ansible run and a second idempotent
|
||||
run passed; the generated unit was inactive, with no staging HTTP/SSH listener. POSIX ACLs on only the
|
||||
service-namespace parents grant this account traversal without access to sibling datasets.
|
||||
- [ ] Perform an isolated rootless restore test from the verified Prometheus backup; validate SQLite,
|
||||
repositories, SSH host keys, and target backups before any traffic cutover.
|
||||
- [ ] After an explicit outage approval, perform the final consistent copy and HTTPS/SSH cutover,
|
||||
then remove Gitea from Prometheus' desired stack and backup export without deleting source data.
|
||||
- [ ] Design and deploy Nextcloud as another explicitly temporary Atlas service before Uranus. Give it
|
||||
|
||||
Reference in New Issue
Block a user